Meine Bibliothek
Meine Bibliothek

+ Zur Bibliothek hinzufügen

Support

Ihre Anfragen

Rufen Sie uns an

+7 (495) 789-45-86

Profil

Android.Triada.5260

Added to the Dr.Web virus database: 2022-03-02

Virus description added:

Technical information

Malicious functions:
Executes code of the following detected threats:
  • Android.Triada.573.origin
Network activity:
Connects to:
  • UDP(DNS) 8####.8.4.4:53
  • TCP(HTTP/1.1) ip####.com:80
  • TCP(HTTP/1.1) gat####.funbl####.io:80
  • TCP(HTTP/1.1) api.applove####.com:80
  • TCP(TLS/1.0) api-acc####.edges####.net:443
  • TCP(TLS/1.0) 1####.250.179.170:443
  • TCP(TLS/1.0) adc-ad-####.ad####.com:443
  • TCP(TLS/1.0) d2####.2usrq####.com:443
  • TCP(TLS/1.0) mt####.ray####.com:443
  • TCP(TLS/1.0) gat####.funbl####.io:443
  • TCP(TLS/1.0) csi.gst####.com:443
  • TCP(TLS/1.0) net.ray####.com:443
  • TCP(TLS/1.0) android####.go####.com:443
  • TCP(TLS/1.0) p####.google####.com:443
  • TCP(TLS/1.0) fk-set####.ray####.com:443
  • TCP(TLS/1.0) adc3-la####.adco####.com:443
  • TCP(TLS/1.0) safebro####.google####.com:443
  • TCP(TLS/1.0) firebas####.google####.com:443
  • TCP(TLS/1.0) wild####.moa####.com.####.net:443
  • TCP(TLS/1.0) api.applove####.com:443
  • TCP(TLS/1.0) www.you####.com:443
  • TCP(TLS/1.0) gd.a.s####.com:443
  • TCP(TLS/1.0) s.openmed####.com:443
  • TCP(TLS/1.0) analy####.ray####.com:443
  • TCP(TLS/1.0) unit####.edges####.net:443
  • TCP(TLS/1.0) res.z####.com:443
  • TCP(TLS/1.0) 2####.58.214.3:443
  • TCP(TLS/1.0) tls.vu####.edges####.net:443
  • TCP(TLS/1.0) digital####.google####.com:443
  • TCP(TLS/1.0) and####.google####.com:443
  • TCP(TLS/1.2) www.you####.com:443
  • TCP(TLS/1.2) 1####.250.179.170:443
  • TCP d2####.2usrq####.com:443
  • TCP analyti####.minte####.net:9377
  • TCP res.z####.com:443
  • TCP analy####.ray####.com:443
DNS requests:
  • a####.go####.com
  • adc-ad-####.ad####.com
  • adc3-la####.adco####.com
  • ads.api.vu####.com
  • analy####.ray####.com
  • analyti####.minte####.net
  • and####.google####.com
  • android####.go####.com
  • api.applove####.com
  • api.vu####.com
  • cd####.vu####.com
  • cdn.app####.com
  • co####.unit####.uni####.com
  • confi####.ray####.com
  • csi.gst####.com
  • d####.fl####.com
  • d2####.2usrq####.com
  • digital####.google####.com
  • firebas####.google####.com
  • gat####.funbl####.io
  • ip####.com
  • mt####.ray####.com
  • net.ray####.com
  • p####.google####.com
  • pv.s####.com
  • res.z####.com
  • s.openmed####.com
  • safebro####.google####.com
  • wcf.seven####.com
  • web####.unit####.uni####.com
  • www.you####.com
  • z.moa####.com
HTTP GET requests:
  • adc-ad-####.ad####.com:443/launch/__controllers__/4.0.0/3.2.2.0/controll...
  • api-acc####.edges####.net:443/api/v5/new?ifa=####&app_id=####
  • api.applove####.com/api/v3/template/get?slot_id=####&update_time=####&us...
  • api.applove####.com/config/client?cc=####&appType=####&osType=####&group...
  • api.applove####.com:443/api/v3/pagead/get?osv=####&srnc=####&token=####&...
  • api.applove####.com:443/video/v4/ad/get?osv=####&srnc=####&token=####&ds...
  • api.applove####.com:443/video/v4/creative/get?osv=####&ispre=####&srnc=#...
  • fk-set####.ray####.com:443/rewardsetting?app_id=####&sign=####&open=####...
  • fk-set####.ray####.com:443/rewardsetting?app_id=####&sign=####&unit_ids=...
  • fk-set####.ray####.com:443/setting?app_id=####&sign=####&open=####&chann...
  • fk-set####.ray####.com:443/setting?unit_ids=####&app_id=####&sign=####&o...
  • gat####.funbl####.io/config/client?cc=####&appType=####&osType=####&grou...
  • gat####.funbl####.io:443/tools/sdk/confign/rewarded/2.5.9/rewarded_confi...
  • gat####.funbl####.io:443/tools/sdk/langs/2.4.4/langs.json
  • gat####.funbl####.io:443/tools/services/4.7.3/config.json
  • gd.a.s####.com:443/cityjson
  • ip####.com/json/?lang=####
  • mt####.ray####.com:443/2021/0629/confirmDialog-2b9fddb88412e09a244a9bb41...
  • res.z####.com:443/1576833642421_5566250.mp4
  • res.z####.com:443/1579245869408_竖屏1.mp4
  • tls.vu####.edges####.net:443/creative/design-framework/assets/vungle-pri...
  • tls.vu####.edges####.net:443/templates/custom_creative_bundles/61e0e80d7...
  • tls.vu####.edges####.net:443/zen/57795a3b0ba4f7f0bcba0f2b3c6def15.mp4-27...
  • unit####.edges####.net:443/webview/3.4.6/release/config.json?ts=####&sdk...
  • unit####.edges####.net:443/webview/3.4.6/release/index.html
  • wild####.moa####.com.####.net:443/VNG/android/fe5b19d/status.json?ts=###...
HTTP POST requests:
  • adc3-la####.adco####.com:443/v4/launch
  • api-acc####.edges####.net:443/api/v5/ads
  • api-acc####.edges####.net:443/config
  • firebas####.google####.com:443/v1/projects/vnow-831a7/installations
  • s.openmed####.com:443/init?v=####&plat=####&sdkv=####&k=####
  • s.openmed####.com:443/om/wf?v=####&plat=####&sdkv=####
File system changes:
Creates the following files:
  • /data/data/####/.YFlurrySenderIndex.info.AnalyticsData_PW4WPX7H...Q8_311
  • /data/data/####/.YFlurrySenderIndex.info.StreamingMain
  • /data/data/####/.old_file_converted
  • /data/data/####/.yflurrydatasenderblock.fcf5e0c9-6395-42ff-bbc4...ac1531
  • /data/data/####/0.f1cc21b6.png
  • /data/data/####/026ae9c9824b3e483fa6c71fa88f57ae27816141
  • /data/data/####/0f88c08ea611aef3_0
  • /data/data/####/0f88c08ea611aef3_1
  • /data/data/####/10.2bb9f35b.png
  • /data/data/####/1af0f7dbe73d5546_0
  • /data/data/####/2.4cd3348d.png
  • /data/data/####/20.384794c3.png
  • /data/data/####/21.c4eb42f3.png
  • /data/data/####/22e85a2e1b1a8433_0
  • /data/data/####/22e85a2e1b1a8433_1
  • /data/data/####/3.573fbdd2.png
  • /data/data/####/30.2f9b85ba.png
  • /data/data/####/31.bd0c9b93.png
  • /data/data/####/32.b87222f1.png
  • /data/data/####/34.3e058ec1.png
  • /data/data/####/35.c6ebd6d5.png
  • /data/data/####/36.8f6e0baa.png
  • /data/data/####/37.3b529239.png
  • /data/data/####/38.4ed29b65.png
  • /data/data/####/4.ed8132d6.png
  • /data/data/####/40.21b86cf6.png
  • /data/data/####/42.acd7421f.png
  • /data/data/####/43.084356dc.png
  • /data/data/####/44.52f0a3a1.png
  • /data/data/####/45.f2af0356.png
  • /data/data/####/46.b0ef0c0c.png
  • /data/data/####/47.8747dce2.png
  • /data/data/####/57795a3b0ba4f7f0bcba0f2b3c6def15.mp4-270x480-h264-Q2.mp4
  • /data/data/####/7.c1140a9a.png
  • /data/data/####/7bf3a1e7bbd31e612eda3310c2cdb8075c43c6b5
  • /data/data/####/8.7753f926.png
  • /data/data/####/9.b8c9cb29.png
  • /data/data/####/AdConfig.xml
  • /data/data/####/AdTimingCrashSP.xml
  • /data/data/####/AppInfo
  • /data/data/####/AppVersion
  • /data/data/####/Cookies-journal
  • /data/data/####/DT_Event.xml
  • /data/data/####/FLURRY_SHARED_PREFERENCES.xml
  • /data/data/####/FirebaseAppHeartBeat.xml
  • /data/data/####/PersistedInstallation.W0RFRkFVTFRd+MToxMDg3ODU4...Q.json
  • /data/data/####/PersistedInstallation1356405237tmp
  • /data/data/####/PersistedInstallation1924369844tmp
  • /data/data/####/RewardedVideo.db
  • /data/data/####/RewardedVideo.db-journal
  • /data/data/####/S2sKBVB25KM01QOAqZPm8BXZX8k-E2xlgB0NIgnVGU4=
  • /data/data/####/S2sKBVB25KM01QOAqZPm8BXZX8k-E2xlgB0NIgnVGU4=.vng_meta
  • /data/data/####/SbqqVlrOdxuYTiHh0GImRbX8I5rRrUnkzNLpWl9PxUw=
  • /data/data/####/SbqqVlrOdxuYTiHh0GImRbX8I5rRrUnkzNLpWl9PxUw=.vng_meta
  • /data/data/####/UnityAdsStorage-private-data.json
  • /data/data/####/UnityAdsStorage-public-data.json
  • /data/data/####/UnityAdsTest.txt (deleted)
  • /data/data/####/UnityAdsWebApp.html
  • /data/data/####/WXovo7QJD8CKQM0WRto-3LheHVvCNx9s-qRfzKuel_k=
  • /data/data/####/WXovo7QJD8CKQM0WRto-3LheHVvCNx9s-qRfzKuel_k=.vng_meta
  • /data/data/####/WebViewChromiumPrefs.xml
  • /data/data/####/_3T29TTi9hvhzqK-PSXGEFpx4x7nTaQR-GH_Wg0Vpmg=
  • /data/data/####/_3T29TTi9hvhzqK-PSXGEFpx4x7nTaQR-GH_Wg0Vpmg=.vng_meta
  • /data/data/####/aa_config
  • /data/data/####/afd1707ad76c449f9c1ce4de75dac80e.zip
  • /data/data/####/androidx.work.workdb-journal (deleted)
  • /data/data/####/androidxu3dqqnc0z.
  • /data/data/####/androidxu3dqqnc0z.dex
  • /data/data/####/androidxu3dqqnc0z.dex.flock (deleted)
  • /data/data/####/appnext_dbs472
  • /data/data/####/appnext_dbs472-journal
  • /data/data/####/asset_package.zip
  • /data/data/####/bg2.png.a557bee1.webp
  • /data/data/####/bg3.png.4e900c08.webp
  • /data/data/####/bg_bonus.a2c28610.png.webp
  • /data/data/####/bg_checkin.f5eab94f.png
  • /data/data/####/bg_game.df720637.png.webp
  • /data/data/####/bg_task65_1.7bb01e2b.png.webp
  • /data/data/####/bg_task65_2.27ee162d.png.webp
  • /data/data/####/bg_task65_3.153d0548.png.webp
  • /data/data/####/bg_task65_end.c92bfee5.png.webp
  • /data/data/####/bg_uinfo.6c25e398.png
  • /data/data/####/btn-refernow-en.fd0fc6ee.png.webp
  • /data/data/####/btn-refernow-hi.f199a4f6.png.webp
  • /data/data/####/btn-refernow-id.9a9fe68e.png.webp
  • /data/data/####/c3fcfa8f0f758a861990ba5c1072499a.mp4-270x480-h264-Q2.mp4
  • /data/data/####/cache_policy_journal
  • /data/data/####/cache_touch_timestamp
  • /data/data/####/challenge-redeemcard-bg.ce234050.png.webp
  • /data/data/####/checkin_coin_more.f05bf511.png.webp
  • /data/data/####/checkintip.9aab093f.png.webp
  • /data/data/####/chunk-039be860.8b7a2930.js
  • /data/data/####/chunk-039be860.ecfb3d83.css
  • /data/data/####/chunk-0d6c19fc.6971f087.css
  • /data/data/####/chunk-0d6c19fc.7a38a91a.js
  • /data/data/####/chunk-112935b8.6d2e0ca8.css
  • /data/data/####/chunk-112935b8.7c2f3597.js
  • /data/data/####/chunk-18277ed4.506cb164.js
  • /data/data/####/chunk-18277ed4.eb4643f3.css
  • /data/data/####/chunk-198d38fe.2c7e6368.css
  • /data/data/####/chunk-198d38fe.36e8ff6a.js
  • /data/data/####/chunk-1c3695fa.29f85c7d.js
  • /data/data/####/chunk-1c3695fa.66929db2.css
  • /data/data/####/chunk-20d6afd0.0bea358c.js
  • /data/data/####/chunk-20d6afd0.d5d7bf07.css
  • /data/data/####/chunk-2a4c20b0.91123d7d.js
  • /data/data/####/chunk-2a4c20b0.b0d394bd.css
  • /data/data/####/chunk-2d0c0846.e511a780.js
  • /data/data/####/chunk-2d0e5e97.7b5ae1af.js
  • /data/data/####/chunk-2d208c0c.e29149ed.js
  • /data/data/####/chunk-2d213786.6b800e50.js
  • /data/data/####/chunk-2e8a2bec.5fa6428f.js
  • /data/data/####/chunk-2e8a2bec.d38a27a2.css
  • /data/data/####/chunk-2ff5e3c4.55faabb7.css
  • /data/data/####/chunk-2ff5e3c4.829d94b9.js
  • /data/data/####/chunk-3053d40c.e8d9e67d.js
  • /data/data/####/chunk-3290b65c.0581418f.css
  • /data/data/####/chunk-3290b65c.78c85774.js
  • /data/data/####/chunk-3ac89ac8.36150551.js
  • /data/data/####/chunk-3ac89ac8.9b88b264.css
  • /data/data/####/chunk-3c958150.63772b04.js
  • /data/data/####/chunk-3c958150.e65e338d.css
  • /data/data/####/chunk-3e70bf22.c6eb95ec.css
  • /data/data/####/chunk-3e70bf22.d9c9ca41.js
  • /data/data/####/chunk-416e4a86.0883cdd4.css
  • /data/data/####/chunk-416e4a86.c47faa11.js
  • /data/data/####/chunk-43e48476.6b32b697.css
  • /data/data/####/chunk-43e48476.fffb7815.js
  • /data/data/####/chunk-441c5675.416833a1.css
  • /data/data/####/chunk-441c5675.68294564.js
  • /data/data/####/chunk-487479c7.ea99a20e.js
  • /data/data/####/chunk-487479c7.f31231df.css
  • /data/data/####/chunk-4879c955.30cd87a2.js
  • /data/data/####/chunk-4879c955.da8fff9c.css
  • /data/data/####/chunk-4cc25658.1f899f8b.js
  • /data/data/####/chunk-4cc25658.9c634c20.css
  • /data/data/####/chunk-4d350800.3cec247d.js
  • /data/data/####/chunk-528752aa.1dbf97e2.css
  • /data/data/####/chunk-528752aa.d2f9eb30.js
  • /data/data/####/chunk-636090c4.8b807ccc.js
  • /data/data/####/chunk-636090c4.c97e86c3.css
  • /data/data/####/chunk-63d61e03.18e8efe3.js
  • /data/data/####/chunk-63d61e03.1ecbad2c.css
  • /data/data/####/chunk-68d6836a.87c9d281.js
  • /data/data/####/chunk-68d6836a.bc0ced64.css
  • /data/data/####/chunk-6c756b73.9d894332.js
  • /data/data/####/chunk-6c756b73.d2e68206.css
  • /data/data/####/chunk-6e2d27ac.336d491e.js
  • /data/data/####/chunk-6e2d27ac.bf26bb9a.css
  • /data/data/####/chunk-8e53b1be.2f25bb0c.js
  • /data/data/####/chunk-8e53b1be.de3c3e1d.css
  • /data/data/####/chunk-b22852b8.285e9881.js
  • /data/data/####/chunk-b22852b8.f04cc715.css
  • /data/data/####/chunk-c3c738b8.3d74f96e.css
  • /data/data/####/chunk-c3c738b8.bb0c17e3.js
  • /data/data/####/chunk-cedf0df0.00218859.css
  • /data/data/####/chunk-cedf0df0.69f9bccc.js
  • /data/data/####/chunk-common.446b37b7.css
  • /data/data/####/chunk-common.fe3f5955.js
  • /data/data/####/chunk-d4ea9016.0657a119.css
  • /data/data/####/chunk-d4ea9016.2598bd7f.js
  • /data/data/####/chunk-ea26b7ac.80f25e47.js
  • /data/data/####/chunk-ea26b7ac.c2ef2c52.css
  • /data/data/####/chunk-eca31988.5f1d9e6e.js
  • /data/data/####/chunk-vendors.205624ff.css
  • /data/data/####/chunk-vendors.b2457925.js
  • /data/data/####/cocos2d-js-min.5ac6a.js
  • /data/data/####/coin-rp.ccf51795.png
  • /data/data/####/coin.50f2d229.mp3
  • /data/data/####/coinbag.2dd8e420.png
  • /data/data/####/com.google.android.datatransport.events-journal
  • /data/data/####/com.google.android.gms.appid-no-backup
  • /data/data/####/com.google.android.gms.appid.xml
  • /data/data/####/com.google.android.gms.measurement.prefs.xml
  • /data/data/####/com.mopub.privacy.xml
  • /data/data/####/com.vd.vidnow_ct_default.xml
  • /data/data/####/com.vd.vidnow_preferences.xml
  • /data/data/####/com.vungle.sdk.xml
  • /data/data/####/common-empty.06c31d82.png.webp
  • /data/data/####/completed-1646205247657
  • /data/data/####/config_ad
  • /data/data/####/config_banner
  • /data/data/####/config_common_en
  • /data/data/####/config_hotword
  • /data/data/####/config_i18n
  • /data/data/####/config_movie
  • /data/data/####/config_native_ad_config
  • /data/data/####/config_share
  • /data/data/####/config_spider
  • /data/data/####/config_website
  • /data/data/####/config_youtube
  • /data/data/####/confirmDialog.html
  • /data/data/####/confirmDialog.js
  • /data/data/####/confirm_dlg_icon.b3e9c568.png.webp
  • /data/data/####/contribution1.9245b44f.png.webp
  • /data/data/####/crashFile
  • /data/data/####/ct_download.db-journal
  • /data/data/####/currentFile
  • /data/data/####/cv.xml
  • /data/data/####/d7711073613e8abb2f6115d497aa126b.0.tmp
  • /data/data/####/d7711073613e8abb2f6115d497aa126b.1
  • /data/data/####/default.0064ab3d.png.webp
  • /data/data/####/default.710f167c.png
  • /data/data/####/defaultavatar.db6c6fec.jpg
  • /data/data/####/detail_bg.2c59a754.png.webp
  • /data/data/####/dialog.a760584f.js
  • /data/data/####/dialog.html
  • /data/data/####/dt_event.db-journal
  • /data/data/####/e49b73494151f26d_0
  • /data/data/####/favicon.ico
  • /data/data/####/fe4d94827e1ccca64a9c4bc7449a3573.0.tmp
  • /data/data/####/feedback.50fc695e.js
  • /data/data/####/feedback.69b5ab05.css
  • /data/data/####/filedownloader.db-journal
  • /data/data/####/game-machine-buddle2.7c2aa443.png
  • /data/data/####/game_block.3c232200.png
  • /data/data/####/gbridge.js
  • /data/data/####/generatefid.lock
  • /data/data/####/godap_download.db-journal
  • /data/data/####/godap_pub_data.xml
  • /data/data/####/google_app_measurement_local.db
  • /data/data/####/google_app_measurement_local.db-journal
  • /data/data/####/hand.1da7be80.png
  • /data/data/####/hand.9d1b51e7.png
  • /data/data/####/head_bg.e318e326.png.webp
  • /data/data/####/head_bg.f67827e7.png.webp
  • /data/data/####/icon-1.14fb6eec.png
  • /data/data/####/icon-2.e30e1cdb.png
  • /data/data/####/icon-3.c04675ce.png
  • /data/data/####/icon-4.0a0152ed.png
  • /data/data/####/icon-5.c0827820.png
  • /data/data/####/icon-coin-shadow.d76e001b.png.webp
  • /data/data/####/icon-coin.2bc2711f.png.webp
  • /data/data/####/icon-rp.c48bedef.png.webp
  • /data/data/####/icon_bonus.f4db21f6.png
  • /data/data/####/icon_game.ba08f404.png
  • /data/data/####/icon_gift.2cb96876.png
  • /data/data/####/icon_q.d7152218.png
  • /data/data/####/icon_step1.dd330b6a.png.webp
  • /data/data/####/icon_step2.741e0511.png.webp
  • /data/data/####/icon_step3.091917e7.png.webp
  • /data/data/####/icon_step4.836b7749.png.webp
  • /data/data/####/icon_task.9146b71f.png
  • /data/data/####/icon_video.92fa2418.png
  • /data/data/####/iconfont.41bd29c2.woff
  • /data/data/####/index
  • /data/data/####/index.56cf364f.js
  • /data/data/####/index.html
  • /data/data/####/index.json
  • /data/data/####/installationNum
  • /data/data/####/journal
  • /data/data/####/lLmMuXlvnb8YWya02RzQ3jlLCTuz_EiqgPtg1n9vzNM=
  • /data/data/####/lLmMuXlvnb8YWya02RzQ3jlLCTuz_EiqgPtg1n9vzNM=.vng_meta
  • /data/data/####/leaderboard-title-en.3ad0730c.png.webp
  • /data/data/####/leaderboard-title-hi.8b0bee22.png.webp
  • /data/data/####/leaderboard-title-id.dcf22970.png.webp
  • /data/data/####/lib_shared_preferences.xml
  • /data/data/####/lib_shared_preferences.xml.bak
  • /data/data/####/loading.json
  • /data/data/####/lottie.min.js
  • /data/data/####/m.bundle.js
  • /data/data/####/mbridge.msdk.db-journal
  • /data/data/####/mbridge.xml
  • /data/data/####/mbridge.xml.bak
  • /data/data/####/mbridge.xml.bak (deleted)
  • /data/data/####/metrics_guid
  • /data/data/####/mix.675b8ab0.js
  • /data/data/####/mix.html
  • /data/data/####/mp4.c62d7fhadbvufgfssmdg
  • /data/data/####/mp4.c62d7fpadbvufgfssmo0
  • /data/data/####/mycrash.log
  • /data/data/####/notlogined.10e7ab83.png.webp
  • /data/data/####/omDB.db
  • /data/data/####/omDB.db-journal
  • /data/data/####/paytm-ico.f76928e1.png
  • /data/data/####/proc_auxv
  • /data/data/####/redeem-result.f4144f00.png.webp
  • /data/data/####/refer-top-bg.5c58d61e.png.webp
  • /data/data/####/refer2.279347f3.png
  • /data/data/####/remote.5bd33d33.js
  • /data/data/####/rise-line.213c6f83.png
  • /data/data/####/rules-steps.27bdbee6.png
  • /data/data/####/share_date.xml
  • /data/data/####/sp_wertwe.xml
  • /data/data/####/splash.4fdde.png
  • /data/data/####/step1.37b5265f.png.webp
  • /data/data/####/step1_2.f7d32f64.png.webp
  • /data/data/####/step2.03747dc4.png.webp
  • /data/data/####/step3.21ce8d7d.png.webp
  • /data/data/####/step4.12671af1.png.webp
  • /data/data/####/steps.c500a65a.png.webp
  • /data/data/####/steps.eb2d52b2.png.webp
  • /data/data/####/style-mobile.css
  • /data/data/####/switch
  • /data/data/####/tasktip-img1.c47ea8fc.png.webp
  • /data/data/####/tasktip-img2.b4d79868.png.webp
  • /data/data/####/tasktip-img3_1.b664a55d.png.webp
  • /data/data/####/template
  • /data/data/####/the-real-index
  • /data/data/####/top_bg.7d4b702b.png.webp
  • /data/data/####/update.zip
  • /data/data/####/update1.d38dc913.png.webp
  • /data/data/####/updatepath.856eaebf.png.webp
  • /data/data/####/video_bg.4c2eb988.png.webp
  • /data/data/####/vungle-privacy.svg
  • /data/data/####/vungle_db-journal
  • /data/data/####/webviewjavascriptbridge.js
  • /data/media/####/.nomedia
  • /data/media/####/UnityAdsTest.txt
  • /data/media/####/UnityAdsTest.txt (deleted)
  • /data/media/####/VDMaster.mmap3
  • /data/media/####/VDMaster_20220302.xlog
  • /data/media/####/afd1707ad76c449f9c1ce4de75dac80e.zip
  • /data/media/####/confirmDialog.html
  • /data/media/####/confirmDialog.js
  • /data/media/####/m.bundle.js
  • /data/media/####/mycrash.log
  • /data/media/####/z
Miscellaneous:
Executes the following shell scripts:
  • app_process /system/bin com.android.commands.pm.Pm list package -3
  • ls -l /system/bin/su
  • sh
Loads the following dynamic libraries:
  • libc++_shared
  • libmarsxlog
  • libmmkv
  • libxcrash
Uses the following algorithms to encrypt data:
  • AES-CBC-PKCS7PADDING
  • AES-CBC-PKCS7Padding
Accesses the ITelephony private interface.
Gets information about network.
Gets information about phone status (number, IMEI, etc.).
Gets information about installed apps.
Adds tasks to the system scheduler.
Displays its own windows over windows of other apps.
Requests the system alert window permission.

Curing recommendations


Android

  1. If the mobile device is operating normally, download and install Dr.Web for Android Light. Run a full system scan and follow recommendations to neutralize the detected threats.
  2. If the mobile device has been locked by Android.Locker ransomware (the message on the screen tells you that you have broken some law or demands a set ransom amount; or you will see some other announcement that prevents you from using the handheld normally), do the following:
    • Load your smartphone or tablet in the safe mode (depending on the operating system version and specifications of the particular mobile device involved, this procedure can be performed in various ways; seek clarification from the user guide that was shipped with the device, or contact its manufacturer);
    • Once you have activated safe mode, install the Dr.Web для Android Light onto the infected handheld and run a full scan of the system; follow the steps recommended for neutralizing the threats that have been detected;
    • Switch off your device and turn it on as normal.

Find out more about Dr.Web for Android